Licensing infrastructure

Licenses that
defend themselves.

Keys get shared. Builds get cracked. Licentry is the licensing API that notices and fights back: hardware-bound activations, proof-of-possession sessions, cryptographically signed responses and per-customer watermarked builds.

P-256 SIGNED RESPONSES· DPoP RFC 9449· HOSTED OR SELF-HOSTED

P-256every signature channel
314-bitbuild token entropy
< 1 heartbeatrevocation propagation
5 endpointsfull client integration
Why Licentry

Most licensing checks return a boolean.
Crackers patch booleans.

Licentry treats licensing as a live, signed, device-bound session, not a one-shot yes/no your attacker flips in a debugger.

Device

Hardware-bound activation

Every activation binds the session to a device fingerprint. A leaked key stops working the moment it leaves the machine it was activated on. Device caps are enforced server-side.

RFC 9449

Proof-of-possession sessions

Short-lived access tokens can be DPoP-bound to a P-256 key held by the client. A stolen token is useless without the private key that never leaves the device.

P-256

Signed responses

Every license response carries an ECDSA P-256 signature your app verifies against pinned public keys. A spoofed server, patched DNS or MITM'd reply fails closed.

Forensics

Watermarked builds

Binaries are patched per download with a unique build token, owner hint and self-hash. When a copy leaks, one query tells you exactly which account it came from.

Evidence

Sharing detection

Concurrent-session caps, per-key device limits, heartbeat sequence tracking and geo evidence trails surface resellers and "family plans" you never approved.

Revocation

Kill switch & canaries

A revocation bump invalidates every running session within one heartbeat. Canary keys act as honeytraps that flag cracker probing before it becomes a problem.


Integration lifecycle

Five endpoints. One afternoon.

The whole client integration is a small, strict state machine. The order below is the order your code runs in.

01

Issue vendor API

Mint 28-character license keys from your dashboard or the vendor API. Keys are HMAC-peppered at rest with a pepper unique to your account, so a database leak alone reveals nothing usable.

02

Activate POST /activate

Your app sends the key, a device hash, and optionally a DPoP public key. It gets back a short-lived session: access + refresh tokens, signed, idempotent on retry.

03

Heartbeat POST /heartbeat

A monotonic sequence counter keeps the session provably alive. Replays and skipped counters are rejected, so cloned sessions surface immediately.

04

Refresh & revoke POST /refresh

Tokens rotate before expiry. When you revoke or freeze a license, the bump invalidates every bound session on its next beat. No waiting for expiry.

client.cpp · integration sketch
// 1. activate once per install
auto s = licentry.activate(key, deviceHash(), dpopJwk());

// 2. verify the response signature (pinned P-256)
if (!verify(s.header("X-Licentry-Sig"), pinnedKeys)) fail_closed();

// 3. heartbeat on a timer, seq strictly increasing
every(minutes(15), [&]{ licentry.heartbeat(++seq); });

// 4. refresh before expiry; re-activate on stale_revocation
before(s.expiresAt, [&]{ s = licentry.refresh(s.refreshToken); });

// offline? verify the ES256 grace JWT (device-bound)
if (offline && graceJwt.dev == deviceHash()) run_grace_period();
Client integration

Ship it in any language.

The client side is five HTTPS calls with JSON bodies, so anything with an HTTP client can run the licensing loop. Signatures are ECDSA P-256: most of these verify it straight from the standard library, the rest with one well-known package. The docs carry copy-paste examples for twelve languages.

Licentry clients can be written in C++, C#, Rust, Go, Python, Node.js, TypeScript, Java, Kotlin, Swift, C, PHP, Ruby, Dart, Objective-C, Lua, Delphi, Elixir, JavaScript, F#, Visual Basic, Scala, Clojure, Groovy, Zig, Nim, Crystal, Haskell, OCaml, Erlang, Julia, R, Perl, PowerShell, Bash and anything else that speaks HTTPS and JSON.

Defense in depth

Built by people who
watch software get cracked.

Every layer assumes the one above it eventually fails. That's the point: defense in depth means a cracked check still doesn't produce a working copy.

  • Indistinguishable failures. Unknown, expired, revoked and canary keys all fail identically, on the same response schedule, so activation can't be used as an oracle to sort live keys from dead ones.
  • Server-held engine parameters. Ship config your app actually needs, sealed to the live session key. Patching the license check out means the app still can't run: there's nothing to run with.
  • Everything audited. Wrong-owner logins, canary hits, replayed heartbeats, HWID resets: every security-relevant event lands in an append-only audit log with actor, IP and evidence.
L7Response signingECDSA P-256
L6Proof-of-possessionDPoP · RFC 9449
L5Build watermarking.lcmrk · HMAC
L4Offline graceES256 JWT · device-bound
L3Canary keysHoneytrap
L2Timing normalizationAnti-oracle
L1Sharing evidenceAudit trail

Deployment

Run it our way. Or yours.

Hosted

Licentry Cloud

We run the API, the database, the key management and the on-call. You get an endpoint, a vendor dashboard and scoped API keys. The fastest way from zero to enforced licensing.

Dedicated

Your own server

A single-tenant server provisioned for your account: your database, your license data, optionally your own Discord bot and API domain. We set it up by hand, harden it and keep it patched. Part of the self-hosted data plan, enabled on request.

Compare

Most tools hand over a key. Then stop.

A key on its own is a string in a database. Everything below is about what happens after the buyer has it: whether anything still checks, and what you can prove when a copy walks.

Capability Checkout platformsGumroad, Paddle Licensing suitesCryptlex, LicenseSpring Key systemsKeyAuth and similar Licentry
Checks the licence while your app is running Live session
Ties a licence to one machine Server-enforced caps
Revoking kills sessions already running Refund only~Next check-in~Varies Within one heartbeat
A stolen token is useless on another machine ~Uncommon~Uncommon DPoP, RFC 9449
Your app can prove the reply really came from us ~Varies~Varies Signed, P-256
A leaked build points back to one buyer ~Uncommon~Uncommon Watermarked download
Evidence when a key gets shared ~Varies~Basic Devices, IPs, canaries
Works in any language, no SDK to wait for ~Webhook onlySDK per platform Five HTTPS calls
You keep every cent you charge Takes a cut Flat monthly fee
Start without talking to a salesperson Annual contract From 19 dollars

does it   ~ depends on the vendor or the tier   not what it is for. Columns describe the usual shape of a category rather than one product, so check the current feature list of anything you are shortlisting.

The four rows almost nobody else ticks

A stolen token is dead on arrival

Sessions are bound to a keypair the device generates and never shares. Copy the token to another machine and it stops working, because the thief cannot sign for it.

A fake server cannot answer for us

Every session response is signed with ECDSA P-256 and verified against a key pinned in your binary. Patched DNS, a proxy or a cracked host all fail closed instead of replying "valid".

Every download is watermarked

Each binary carries its own build token, owner hint and self-hash. When a copy shows up on a forum, one query names the account it was issued to.

Sharing leaves a trail

Concurrent sessions, device counts, network changes and heartbeat gaps become a verdict you can act on, and canary keys flag people probing your product before it spreads.

Selling, not enforcing

Gumroad, Lemon Squeezy, Paddle

They take the payment and email a key. Nothing checks that key while your software runs, so a copy posted in a forum keeps working forever. Many vendors keep theirs and add Licentry underneath: they handle checkout, we enforce the licence.

Built for large software vendors

Cryptlex, LicenseSpring, Thales Sentinel

Mature suites with native SDKs, floating licences, offline activation and dongles. If you sell into enterprises with air-gapped installs and procurement paperwork, that is genuinely their ground. The cost is an SDK per platform and a sales process to get started.

Closest in spirit

Keygen

Developer-first licensing over an HTTP API with a source-available core you can host yourself. Same instinct as ours: no SDK to wait for. We put our effort lower down, into the anti-tamper layer and the forensics that name the account behind a leak.

Same audience, different build

KeyAuth and similar

Cheap, quick to bolt on, hardware locking and reseller flows included. We cover that ground and add the hardened session protocol above, with every vendor's signing keys and key hashes sealed under their own crypto so one tenant's bad day is not everyone's.

Partners

Proven in production.

Licentry keys are already doing real work in the wild.

Advanced Mechanics PARTNER 001

Our first official partner. Belgium-based Advanced Mechanics licenses its software with Licentry: hardware-bound keys, runtime sessions and signed responses for 1,500+ customers.

advanced-mechanics.com
Plans

Early access. Founding rates.

Licentry is onboarding its first wave of vendors. Founding integrations lock their launch rate for life. Billing is crypto first, no KYC; card works through support. Every account opens as a free one-week dev trial: 1 product, 3 keys, wiped unless you subscribe.

Indie

For a first product

$19 /mo

or $150/yr (34% off)

  • Hosted licensing API
  • 500 active licenses
  • Up to 3 products
  • Device binding & session caps
  • Signed responses
Get started
Most popular

Studio

For serious catalogs

$79$59 /mo

or $468/yr (34% off) · founding rate

  • Everything in Indie
  • 5,000 active licenses
  • Up to 15 products
  • Discord bot: redeem panel, key commands, activity logs
  • DPoP sessions & offline grace
  • Sharing evidence & canary keys
  • Priority support
Get started

Self-hosted data

Your own dedicated server, fully managed

  • A dedicated server provisioned for your account alone. We set it up by hand, secure it and keep it patched
  • Your database and license data live on that server; the license cap is what the hardware holds, not a plan number
  • Your own Discord bot: hand us the token and it runs from your server, under your branding, separate from the shared Licentry bot
  • API on your own domain once you point DNS at us, or the standard licentry.cc endpoints
  • Everything in Studio, plus dedicated priority support from the engineer who runs your server
  • Priced per setup, server and upkeep included · limited slots
Talk to us

CRYPTO BILLING, CARD VIA SUPPORT · MONTHLY OR YEARLY · NON-KYC · FOUNDING INTEGRATIONS LOCK THE LAUNCH RATE.

NEED MORE ROOM? ADD EXTRA ACTIVE LICENSES TO ANY PAID PLAN, $1 PER 100 PER MONTH, UP TO 10,000 EXTRA.

FAQ

Common questions

How long does integration take? +

The core loop is five endpoints: validate, activate, heartbeat, refresh, logout. A minimal integration is an afternoon; adding response-signature pinning, DPoP and offline grace is typically another day. The docs walk through every step with copy-paste examples.

Which languages and platforms are supported? +

Anything that speaks HTTPS and JSON. There is no SDK to wait for: the client side is five endpoints. Every signature channel is ECDSA P-256 specifically so native Windows clients can verify with built-in BCrypt and no extra crypto dependencies. The docs carry working examples in twelve languages, C++, C#, Python, Node.js, Go, Rust, Java, PHP, Swift, Kotlin, Ruby and plain cURL, and you can switch the whole page to yours with one click.

What actually happens when a key leaks? +

Device caps stop it activating on new machines. Concurrent-session caps stop parallel use. The sharing-evidence view shows you devices, IPs and geography per key. One click bumps the revocation version and every bound session dies on its next heartbeat. If the leak was a whole binary, its watermark tells you which account it came from.

Do licensed apps work offline? +

Yes. Activation can return a short-lived, device-bound offline-grace token (an ES256 JWT your app verifies locally). You choose the TTL, from 1 hour to 7 days. Revoked licenses run out of grace instead of running forever.

Can we self-host Licentry? +

The self-hosted data plan gives you a dedicated server of your own. We provision it manually, secure it and keep it updated; your database and license data live there instead of on shared infrastructure, with room for as many licenses as the hardware holds. It can also run your own branded Discord bot (you hand us the token, we host and wire it up) and serve the API from your own domain once you point DNS at us. The licensing engine itself stays managed by us, so there is nothing for you to patch. Pricing is per setup since needs differ, and slots are limited because every server is maintained personally. Write to [email protected] to talk it through.

How do payments work? +

Crypto first, no KYC. You upgrade from the dashboard and pay a crypto invoice; the plan activates the moment the payment settles on-chain. If card is your only option, write to [email protected] and we handle it manually.

Get started

Ship software that
stays paid for.

Integrate in an afternoon. Sleep through the next crack attempt.